Compliance software · EU AI Act · Brussels

When the auditor asks for your AI Act file, it already exists.

Euridium registers each AI system, classifies it under the EU AI Act, lists the obligations for your role, and keeps the evidence, the sign-offs and the audit trail together. One file per system, ready to hand over.

Live: registry, classification, obligations, evidence, sign-off, audit trail    In build: AI drafting of the file, December 2026

app.euridium.eu · Lendora Score · Obligations
Obligations of one system, article by articleThe evidence attached to one systemThe hash-chained audit trailThe AI registry: systems, risk tier, owner, readiness

Obligations · Lendora Score · 34 obligations under the AI Act · 5 self-attested

Selected for the FARI AI Accelerator 2026Founder: 27 published analyses on AI law, a year of AI Act trainingBuilt in BrusselsDemo data: Lendora, a fictional fintech
Annex IV · §3Data and data governance

↳ training-data-sheet-v3.2.pdf · p. 2↳ model-risk-register · row 14

§3.4 · Bias monitoringNo source found in the uploaded documents. Question for the team: is post-deployment bias monitoring documented anywhere?
Signed · Head of Risk · 14 Sep 2026→ chain #0043
In build · demo December 2026

Next: the AI writes the first draft from your documents.

Policies, supplier contracts, model cards, technical notes. The model reads them and drafts each section the law expects, every sentence linked to the passage it came from. Where it finds nothing, it writes nothing and says which question to ask your team.

  • Drafts with sources, or not at all
  • Never signs: “Compliant” stays locked behind evidence and a person
  • Never classifies: risk tiers stay deterministic and auditable
  • First demonstration in December 2026, on the real documents of the first pilots

Live today

What the application already does.

Everything below comes from the demo workspace, a fictional fintech with three AI systems. Nothing is a mock-up.

Live

Registry & classification

Each system gets a risk tier, and the reason is written out.

Same answers, same tier, every time. No language model anywhere near that decision.

Lendora Score · credit scoringHigh risk · Annex III
Talent Screen · CV rankingHigh risk · Annex III
Lendora Assist · chatbotLimited risk · Art. 50
RoleProvider · Deployer · Deployer
Live

Obligations

Thirty-four obligations for one high-risk model, each with its test.

Why it exists, when it is met, what evidence is expected, the ISO 42001 mapping.

Documented risk-management systemArt. 9 · critical · AI Act
Compliant
WhyRisk management is continuous over the lifecycle of a high-risk system.
Compliant ifA documented process to identify, evaluate and mitigate risks, kept up to date.
EvidenceRisk-management file · 2 attached
Live

Evidence

One document counts for every obligation it covers.

Attach it once. It serves the AI Act today and DORA or GDPR later.

training-data-sheet-v3.2.pdfuploaded 14 Sep 2026
Live

Sign-off

“Compliant” needs evidence and a named signature.

The database refuses anything else. A one-person sign-off is marked as such.

Risk managementOpenEvidence attachedCompliant · signed
Evidencerisk-management-policy-v2.1.pdf
Signed byHead of Risk · 14 Sep 2026
Live

Audit trail

Every action enters a hash chain an auditor can verify.

Who did what, when. Nobody has to trust Euridium.

#0042 evidence.attach8b17e0…04ac
#0043 conformity.attestc4d8a1…9f22
#0044 document.generate61ff7b…b3e0
chain.verify✓ 67 entries · intact
Live

The file

The Annex IV documentation, section by section, as PDF.

Two sections are filled from your assessment answers today. The AI drafting will fill the rest.

Technical documentation — Lendora Score v3.23 / 8 sections completed · Export PDF
  • System identity & classification
  • Obligations covered
  • General description
  • System architecture & design
  • Data & data governance
  • Capabilities & performance
  • Human oversight
  • Accuracy, robustness & cybersecurity
Live

Coverage

The AI Act first. Seven other regimes in the same catalogue.

200 obligations across eight EU regimes, on the same objects. A regime is switched on when a customer needs it, never a separate tool.

AI Act · nowDORA · nextGDPRNIS2Cyber Resilience ActData ActDSADMA

How a file gets built

Three steps. At the end, a dated and signed file.

Register the system

Name it, answer the classification questions, name an owner. The engine derives the tier and the obligations for your role.

Registry → New assessment → 34 obligations generated

Attach evidence, sign

Upload the policy, the contract, the model card. Attach each to the obligations it covers. A named person signs.

Evidence 8 → Risk management · Compliant · signed

Hand over the file

Export the Annex IV documentation and the audit trail. The chain proves nothing was changed after the fact.

Documents → Export PDF · 67 entries · chain verified

Why now

The AI Act obligations land in waves.

2 Feb 2025in force

Prohibited practices, AI literacy

Unacceptable-risk uses banned; staff must be AI-literate.

2 Aug 2025in force

General-purpose AI

Obligations for GPAI model providers, governance, penalties.

2 Aug 2026in force

Transparency

Chatbots must say so; synthetic content and deepfakes must be marked.

2 Dec 2027

High-risk systems

Credit scoring, insurance pricing, recruitment, education, essential services.

2 Aug 2028

AI inside regulated products

AI as a safety component of machinery, medical devices, vehicles.

444
days until 2 December 2027

An Annex IV file takes months to assemble. The companies that buy from you have already started asking for it.

Provider or deployer: which file is yours

Dates as amended by Regulation (EU) 2026/1744. Always confirm against the Official Journal.

Who it is for

Two kinds of companies, the same file.

Companies that build or run AI, without a legal team

Fintechs, AI providers, HR and health software, insurtechs. Twenty to two hundred people, AI in the product, compliance landing on the CTO.

  • A December 2027 deadline that cannot be missed
  • Clients already asking for the AI Act file
  • No budget for a law firm, no time for a spreadsheet

Banks and insurers, together with their suppliers

A financial institution must verify its AI and ICT suppliers under the AI Act and DORA. A bank pilot starts with its own systems; the supplier side follows.

  • Belgian finance first, where auditors and budgets already exist
  • Proof requests to suppliers, free supplier profile In build
  • DORA register of information In build

One law, twenty-seven countries

The same regulation from Lisbon to Tallinn.

The AI Act reads the same in every member state, so a file produced in Euridium works in any of them. We start in Belgian finance and sell in Europe.

AI Act · nowDORA · nextGDPRNIS2CRAData ActDSADMA

Pricing

Launch pricing, indicative.

Per regime and per system. Hypotheses until the first pilots confirm them; founding customers keep the terms they sign.

Starter
€300–800 / month

A company without a legal team. One regime, a few systems, self-serve.

Financial deployer
€1,500–5,000 / month

A bank, insurer or lender with several high-risk systems and an auditor to satisfy. Supplier proof requests and the DORA module are in build.

Supplier profile
Free

Paid for by the buyer that requires it. The way suppliers will join. In build

See it on one of your own systems.

Thirty minutes on the demo workspace, or on a system of yours. The application, not slides. Or start with the free check: six questions, no account.

Nicolas Heynderickx

I trained companies on this regulation for a year before building anything. Nobody in those rooms needed another explanation of the AI Act. They needed the file written, and someone to say it was true. That is the whole product.

NICOLAS HEYNDERICKX · FOUNDER · BRUSSELS